If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
2020-10-12T14:15:12.183
2024-11-21T05:02:11.967
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | tomcat | 8.5.0 | Yes |
Application | apache | tomcat | 8.5.1 | Yes |
Application | apache | tomcat | 8.5.2 | Yes |
Application | apache | tomcat | 8.5.3 | Yes |
Application | apache | tomcat | 8.5.4 | Yes |
Application | apache | tomcat | 8.5.5 | Yes |
Application | apache | tomcat | 8.5.6 | Yes |
Application | apache | tomcat | 8.5.7 | Yes |
Application | apache | tomcat | 8.5.8 | Yes |
Application | apache | tomcat | 8.5.9 | Yes |
Application | apache | tomcat | 8.5.10 | Yes |
Application | apache | tomcat | 8.5.11 | Yes |
Application | apache | tomcat | 8.5.12 | Yes |
Application | apache | tomcat | 8.5.13 | Yes |
Application | apache | tomcat | 8.5.14 | Yes |
Application | apache | tomcat | 8.5.15 | Yes |
Application | apache | tomcat | 8.5.16 | Yes |
Application | apache | tomcat | 8.5.17 | Yes |
Application | apache | tomcat | 8.5.18 | Yes |
Application | apache | tomcat | 8.5.19 | Yes |
Application | apache | tomcat | 8.5.20 | Yes |
Application | apache | tomcat | 8.5.21 | Yes |
Application | apache | tomcat | 8.5.22 | Yes |
Application | apache | tomcat | 8.5.23 | Yes |
Application | apache | tomcat | 8.5.24 | Yes |
Application | apache | tomcat | 8.5.25 | Yes |
Application | apache | tomcat | 8.5.26 | Yes |
Application | apache | tomcat | 8.5.27 | Yes |
Application | apache | tomcat | 8.5.28 | Yes |
Application | apache | tomcat | 8.5.29 | Yes |
Application | apache | tomcat | 8.5.30 | Yes |
Application | apache | tomcat | 8.5.31 | Yes |
Application | apache | tomcat | 8.5.32 | Yes |
Application | apache | tomcat | 8.5.33 | Yes |
Application | apache | tomcat | 8.5.34 | Yes |
Application | apache | tomcat | 8.5.35 | Yes |
Application | apache | tomcat | 8.5.36 | Yes |
Application | apache | tomcat | 8.5.37 | Yes |
Application | apache | tomcat | 8.5.38 | Yes |
Application | apache | tomcat | 8.5.39 | Yes |
Application | apache | tomcat | 8.5.40 | Yes |
Application | apache | tomcat | 8.5.41 | Yes |
Application | apache | tomcat | 8.5.42 | Yes |
Application | apache | tomcat | 8.5.43 | Yes |
Application | apache | tomcat | 8.5.44 | Yes |
Application | apache | tomcat | 8.5.45 | Yes |
Application | apache | tomcat | 8.5.46 | Yes |
Application | apache | tomcat | 8.5.47 | Yes |
Application | apache | tomcat | 8.5.48 | Yes |
Application | apache | tomcat | 8.5.49 | Yes |
Application | apache | tomcat | 8.5.50 | Yes |
Application | apache | tomcat | 8.5.51 | Yes |
Application | apache | tomcat | 8.5.52 | Yes |
Application | apache | tomcat | 8.5.53 | Yes |
Application | apache | tomcat | 8.5.54 | Yes |
Application | apache | tomcat | 8.5.55 | Yes |
Application | apache | tomcat | 8.5.56 | Yes |
Application | apache | tomcat | 8.5.57 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.0 | Yes |
Application | apache | tomcat | 9.0.1 | Yes |
Application | apache | tomcat | 9.0.2 | Yes |
Application | apache | tomcat | 9.0.3 | Yes |
Application | apache | tomcat | 9.0.4 | Yes |
Application | apache | tomcat | 9.0.5 | Yes |
Application | apache | tomcat | 9.0.6 | Yes |
Application | apache | tomcat | 9.0.7 | Yes |
Application | apache | tomcat | 9.0.8 | Yes |
Application | apache | tomcat | 9.0.9 | Yes |
Application | apache | tomcat | 9.0.10 | Yes |
Application | apache | tomcat | 9.0.11 | Yes |
Application | apache | tomcat | 9.0.12 | Yes |
Application | apache | tomcat | 9.0.13 | Yes |
Application | apache | tomcat | 9.0.14 | Yes |
Application | apache | tomcat | 9.0.15 | Yes |
Application | apache | tomcat | 9.0.16 | Yes |
Application | apache | tomcat | 9.0.17 | Yes |
Application | apache | tomcat | 9.0.18 | Yes |
Application | apache | tomcat | 9.0.19 | Yes |
Application | apache | tomcat | 9.0.20 | Yes |
Application | apache | tomcat | 9.0.21 | Yes |
Application | apache | tomcat | 9.0.22 | Yes |
Application | apache | tomcat | 9.0.23 | Yes |
Application | apache | tomcat | 9.0.24 | Yes |
Application | apache | tomcat | 9.0.25 | Yes |
Application | apache | tomcat | 9.0.26 | Yes |
Application | apache | tomcat | 9.0.27 | Yes |
Application | apache | tomcat | 9.0.28 | Yes |
Application | apache | tomcat | 9.0.29 | Yes |
Application | apache | tomcat | 9.0.30 | Yes |
Application | apache | tomcat | 9.0.31 | Yes |
Application | apache | tomcat | 9.0.32 | Yes |
Application | apache | tomcat | 9.0.33 | Yes |
Application | apache | tomcat | 9.0.34 | Yes |
Application | apache | tomcat | 9.0.35 | Yes |
Application | apache | tomcat | 9.0.36 | Yes |
Application | apache | tomcat | 9.0.37 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Application | apache | tomcat | 10.0.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |
Application | oracle | instantis_enterprisetrack | 17.1 | Yes |
Application | oracle | instantis_enterprisetrack | 17.2 | Yes |
Application | oracle | instantis_enterprisetrack | 17.3 | Yes |
Application | oracle | sd-wan_edge | 9.0 | Yes |